An ISASecure SDLA certificate is granted for a fixed term and stays in force for that term without anyone coming back to look: no annual visit, no surveillance audit, no suspended state. When the term ends the certificate expires, and the only way to keep it is a recertification audit completed before that date. Suppliers who expect a product-style surveillance cycle misjudge both the term and what keeps it. This article sets out the lifecycle as ISASecure SDLA-300 and SDLA-200 define it.
What the certificate states, and the date on it
An SDLA certificate certifies a development organization and a specific, version-controlled version of its secure development process, never a product. Under the format prescribed in SDLA-205 and the wording rules in SDLA-204, it carries a certificate number and date; the names of the process and the supplier; the development organization or organizations covered; a statement of conformance to ISASecure SDLA 3.0.0, with the errata version in force, and to IEC 62443-4-1:2018 and its ANSI/ISA equivalent; a pointer to the normative document list; the process versions it applies to, given as a version number or later; the expiry date; the authorized signatory; and the identity and licence number of the issuing chartered laboratory. Wording and placement are fixed, alterations need ASCI approval, and the graphical ISASecure symbol may not appear on an SDLA certificate.
Two of those elements drive everything that follows: the ISASecure version, since every SDLA certificate granted since 1 January 2021 is issued against SDLA 3.0.0, and the expiry date, set at the grant and moved only by a further audit.
36 months or 12: the evaluation method sets the clock
SDLA has no certification levels and no maturity levels; every requirement applicable to the declared scope of the process must pass. What varies is the evaluation method agreed for each requirement. A full evaluation examines the documented process and, for the 21 rows where SDLA-300 makes execution artifacts mandatory, proof that it has been run on real products. A readiness evaluation accepts, for those rows, evidence that the organization is equipped to run the process, such as training, tools and templates, in place of proof of execution.
| How the requirements were passed | Initial validity | How it continues |
|---|---|---|
| Every requirement by full evaluation | 36 months | Recertification audit before expiry |
| Any requirement by readiness evaluation | 12 months | Full evaluation of the readiness rows by month 12; the extended certificate expires 36 months after the original grant |
The evaluation method is agreed per requirement. A single requirement passed by readiness evaluation sets the whole certificate at 12 months. Source: ISASecure SDLA-300 v1.9 (with the SDLA-102 erratum).
SDLA-300 R8 attaches the consequence. When every requirement passed by full evaluation, the certificate runs to the end of the 36th month after the grant. If even one requirement passed only by readiness evaluation, it runs to the end of the 12th month. There is no averaging: the weakest method on any one row sets the term for the whole certificate. This is why "three years" is the wrong answer to how long an SDLA certificate lasts. Thirty-six months is the full-evaluation case; a certificate with readiness rows is a twelve-month certificate.
Extending a 12-month certificate
A 12-month certificate is a certificate with an open item. SDLA-300 R12 provides for its extension once every requirement that passed by readiness has since passed a full evaluation. Two details matter. The extended certificate expires 36 months after the original 12-month grant, not 36 months after the extension. And the extension must be achieved by the end of the 12th month; if it is not, the certification expires and the organization starts again as an initial certification, with every requirement evaluated afresh.
No surveillance: the certificate runs to its date
Many schemes keep a certificate alive through periodic surveillance. ISASecure ICSA is one: its Security Maintenance Audit re-examines four IEC 62443-4-1 requirements (DM-1, DM-2, DM-4 and SUM-5) at intervals ICSA-301 sets and can lead to suspension or withdrawal. SDLA is built the other way round. SDLA-200, the requirements on chartered laboratories, records that surveillance is not required for SDLA certifications: they run to their expiry date, and the whole process is re-examined at recertification, not piecemeal in between.
So keeping the certificate rests on one event, a recertification audit completed before the expiry date. A certificate that reaches expiry without one has lapsed, and SDLA-300 R9 treats a lapsed certification as a new initial certification.
The recertification audit
SDLA-300 R10 gives the audit two subjects. First, that any changes made to the certified process since the last evaluation comply with the SDLA version current at the time of the audit, which is also how changes to the scheme's own criteria reach a certified organization: at the next recertification, not mid-cycle. Second, that the organization has actually been working to its current process, in full, on the products the certificate covers: an adherence audit, not a document review.
Where one secure development process is shared across several development organizations, the check of that common process can be reused from one organization's recertification to another's, provided it is no more than a year old.
The three outcomes
Findings at recertification are classed as major or minor. A major nonconformity is one where there is no evidence that a requirement is met or, for one of the 31 minimum requirements, evidence that it is met inconsistently; any other requirement not met is a minor nonconformity. SDLA-300 Table 1 then allows three outcomes.
| Finding at the recertification audit | What happens to the certificate |
|---|---|
| No nonconformities | Extended for 36 months, counted from the previous expiry date |
| Minor nonconformities only | Extended, provided no minor finding has stayed open since the previous recertification; the open items are re-examined at the next one |
| Any major nonconformity | Extended only if, before the expiry date, the root cause has been corrected in both the process and the organization's internal audit function, one execution of the corrected process has been verified, and no minor finding has stayed open since the previous recertification; otherwise the certificate expires on its date |
Three points follow. A clean recertification does not restart the clock from the audit date; the new term is counted from the old expiry. Minor findings are tolerated once, not indefinitely. And a major finding is not fatal in itself, but the correction is judged against the expiry date, so an audit held close to expiry leaves little room to recover.
As an ISASecure certification body, Perseus takes each of those decisions, grant, extension or expiry, through a decision maker who took no part in the audit, as ISO/IEC 17065 requires.
The intermediate audit
An audit may be requested between recertifications. Under SDLA-200 R25, where the scheme's criteria change during a certificate's term, the client may ask for an intermediate audit against the new criteria rather than wait. It cannot damage the certificate's standing, but it can move the certificate onto the newer ISASecure version.
Termination only: no suspension, withdrawal or reduction
SDLA defines no suspended, withdrawn or reduced state for a certificate. The one change of status short of expiry is termination at the certified organization's request, which the chartered laboratory must support and must report to ISCI, the scheme owner, when it occurs. An SDLA certificate is therefore either in force, terminated or expired. And once a certification has expired or been terminated, the organization may not refer to having held it, until it completes an initial certification again.
What a certified organization may say
The public status information ISCI maintains names the development organization or organizations, the process, the ISASecure version and the expiry date, so those four facts are always checkable. On its own materials a certified organization uses the SDLA symbol in text form only, the scheme name and version with the certificate number; the graphical symbol belongs to product certifications. It may say that a product family, or products of a given kind, are developed under the certified process. It may not assert that any particular product or version was, because the certificate does not say so: a product certification (CSA, ICSA or SSA) is what examines that product's own development artifacts.
For suppliers
Fix the expiry date the day the certificate arrives and work back from it. If any row passed by readiness, the date is twelve months out and the full evaluation of those rows is the first job. Otherwise the recertification audit is the one event that keeps the certificate, and the outcomes table argues for holding it well before expiry. Keep records of process adherence continuously: the audit checks that the process is followed, not only that it is documented.
For asset owners
Read the expiry date, the ISASecure version and the named organizations, and check them against the public status information. The certificate makes no claim about any particular product; that comes from the product's own certificate, which itself depends on the SDLA certificate being current. Two product schemes lean on the SDLA certificate: after the first audit, ICSA's maintenance audits normally fall at each SDLA recertification, and a CSA certificate's coverage of product updates holds only while it is valid.
Where to go next
The CSA prerequisite article covers what a product certification takes from the SDLA certificate, and the ICSA maintenance audit article is the contrast case. The rest of this series is on the SDLA filter of the Insights index.
Frequently asked questions
It depends on how the requirements were passed. When every requirement passed by full evaluation, the certificate runs to the end of the 36th month after the grant. If any requirement passed only by readiness evaluation, it runs to the end of the 12th month. There is no flat three-year term: 36 months is the full-evaluation case, and a certificate with even one readiness row is a 12-month certificate until the readiness rows have been passed by full evaluation.